
Learn to issue PKI certificates with Active Directory Certificate Services on Windows Server for securing servers and computers. Explore VPN certificates, code signing, and digital signatures for authenticated communications.
If you have little knowledge on how to set up a domain controller or join your computers to a domain. Please watch the following extra videos.
Watch Video on How to Install and Configure Active Directory: https://www.youtube.com/watch?v=nn8We7_5LEU
Watch Video on How to join Computer to a Domain Controller: https://www.youtube.com/watch?v=EfyhhJaOhTs
Upgrade Server 2008 to Server 2012 or 2016: https://www.youtube.com/watch?v=QUHV9rqnA-o
Create user accounts in a new domain and configure a certificate template with one-year validity for domain users. Test the manual enrollment workflow from a client PC to verify issuance.
Configure manual enrollment for computer accounts by adjusting security permissions, selecting the computer set, and using a domain administrator to request certificates.
Configure auto enrollment of certificates by enabling public key policies in group policy, then update domain policies and verify user certificate enrollment on client machines.
Configure key recovery agents in the ADCS server 2016, create a dedicated key recovery agent user, and issue a certificate template to support recovering a lost key.
Discover how to issue and export a key recovery agent certificate in ADCS server 2016, and set up a secure central repository for recovery keys.
Examine how a user loses a certificate in an ADCS 2016 environment, including compromised accounts, a lost certificate, and recovery via the key recovery agent account.
Discover how to recover a lost certificate in an ADCS environment by signing in with the recovery agent, locating the archived key in the central store, and importing the certificate.
Learn how to issue a recovered certificate to a user, import the certificate after deletion or lock, and configure certificate authority settings in an ADCS server 2016 environment.
Configure the root CA to publish CRL distribution points and AIA locations, publish to a web server, and specify the server DNS name to enable client access.
Configure domain level certificate policies by deploying public key policies and root certificates through computer configuration in group policy, publish the issuing CA, and update policies across all domain computers.
Configure the issuing subordinate CA in a Windows AD CS environment, process certificate requests, and issue certificates.
Install a certificate on a subordinate certificate authority using the management console, copy required files, configure the webroot and templates, and start services to complete the certificate setup.
install ces, cep, online responder, and ndes to set up certificate services and begin the installation, followed by post-install configuration.
Configure a domain service account for the network device and enrollment services (CES/ CEP/ Online Responder and NDES), and enable enrollment web service authentication and SSL policy.
Configure the computer account certificate on an external or public client by importing the certificate, establishing trust, setting credentials, configuring the server agent, and validating policy.
Practice issuing a web server certificate from a subordinate CA by creating and managing certificate templates, configuring enrollment policies, and assigning permissions to enable automatic issuance to the web server.
Configure online responders by selecting a dedicated certificate and templates in the enterprise certificate authority console, securing permissions, and testing the location configuration to handle multi-cpu certificate requests.
Most employers want Network professionals who have complete knowledge of Digital network security including the practical know-how due to the increasing cyber-attack in recent times.
Computer Security Personnel or Security Specialists earn an average of $77,667 per year. Digital network security knowledge is a must to have.
Undertaking this boot-camp will equip you with the following knowledge;
Build a secured domain network issuing digital certificate to all users
Build a secured domain network issuing digital certificate to all computers
Configure Key Recovery Agent to recover lost certificate keys
Build an Offline Root Certificate Authority for any Enterprise network
Build a Subordinate Certificate Authority for any Enterprise network
Configure Certificate Web Enrolment Service for any Enterprise network
Configure Certificate Web Enrolments Policy for any Enterprise network
Configure Network Device Enrolment Service for any Enterprise network
If you want to also get into the cloud computing space, this is a great start as well, especially if you work with on-premises servers or systems.
Your company will be looking forward to getting into the cloud space by starting with the hybrid style. In this case, some services or servers will be migrated to the cloud will some still remain on-premises and you will be required to manage them.
In summary, investing your time and money into this bootcamp will go a very long way.